Data protection and AI compliance
Getting your personal data and your use of AI in order, before a client or a regulator asks.
Every AI tool your team uses processes somebody’s data, and almost never with anything written down. I map what you process, on what legal basis and which systems see it, and hand you what is missing: the record of processing, the processor contracts, the published notices and the protocol for when something leaks.
Who it is for
- Businesses already using AI in support, sales or back-office
- Practices and advisers handling third-party documentation
- Startups whose compliance will be audited before the money arrives
- Businesses processing health, minors’ or biometric data
Why it ends up being needed
The team is already using artificial intelligence. Not because anyone decided to: because someone tried a tool that saved them half an hour a day and showed it to the person next to them. Today there are client documents pasted into a chat, CVs summarised by a model and emails drafted with data that should never have left the system.
None of those people is doing anything odd. The problem is that nobody wrote down what may be passed to an AI and what may not, and without that sentence in writing everyone decides for themselves, in good faith. When a complaint arrives, or a client asks, or an audit comes before an investment round, there is nothing to show.
What gets delivered here is not a report to file: it is the paperwork done and the rule written. The processing register required by article 30, the contracts with every provider handling data on your behalf, the notices you publish, the inventory of which tool each area uses, and who does what in the first seventy-two hours if something leaks.
What I deliver
- Record of processing — What you process, on what basis, who sees it and how long it is kept.
- AI systems inventory — What each team uses, with what data, and who checks the output.
- Impact assessment — Where the processing calls for one, with the measures that lower the risk.
- Processor contracts — Data-processing clauses for the tools you already use.
- Notices and wording — Privacy, consent and the disclosure for AI-generated content.
- Breach protocol — Who does what in the first hours, written down and rehearsed once.
What is included
- Record of processing
- AI systems inventory
- Contracts and wording
- Breach protocol
What gets decided before a line is written
- What legal basis each processing rests on — It is the question that orders everything else and it is hardly ever answered. Processing a client's data to perform a contract is not the same as processing it to send them marketing: it changes what you may do, how long you keep it and what you must be able to prove. It is decided processing by processing, not in one go.
- Which tools go into the inventory — All the ones the team uses, not the ones that are approved. The gap between those two lists is the first finding of nearly every assessment, and hiding it does not remove it: it just leaves it outside the safeguards.
- Whether an impact assessment is required — Article 35 requires one in specific cases, and the sole-trader exemption falls away as soon as two of the authority's criteria are met. It is checked against the official list and the reasoning is written down, which is what gets asked for if anyone queries it.
- What may be passed to an AI — The most useful output of the whole engagement fits on one page: which data may go to a model, which is replaced first and which never leaves. Written so the team can apply it without asking every time, because a rule you have to look up is a rule nobody follows.
What is not included
- Legal advice or representation: this is compliance work, not a law firm.
- Acting as your organisation's data protection officer.
- Filing anything with the supervisory authority on your behalf.
- Implementing the technical measures in your systems, quoted as development work.
- Security auditing: that is the cybersecurity service.
What you need to have
- Half an hour of conversation with one person from each area that handles data.
- The list of tools actually in use, including the ones nobody approved.
- Access to the contracts you already have signed with providers.
- Who decides in your organisation when there are two valid options.
Frequently asked questions
Is this signed off by a lawyer?
No, and that is why it costs what it costs. This is compliance work: assessment, documentation and technical measures. When legal judgement is needed — a clause that will be argued over, a dispute already open — I say so, and a lawyer signs that.
Does a sole trader with no employees still need a register?
The article 30(5) exemption falls away as soon as the processing is not occasional or involves special categories, which is normal once you have clients and payroll. In practice, almost any small business needs one.
Is it any use if the team uses ChatGPT on their own?
It is, and that is usually the first finding. What comes out of this is what may be passed to an AI and what may not, written so the team can apply it without having to ask every time.
How long does it take?
The assessment is a week of short interviews, and delivery depends on how many areas and tools there are. The quote comes in writing after the first contact, once the real size is known.
Do I have to repeat this every year?
Not all of it. It is reviewed at six months, and sooner if a tool or the law changes. The register is a living document: what makes it useless is not touching it when something changes.
What if I already did the GDPR work years ago?
It gets reviewed and whatever still holds is kept. What is usually missing is the AI part: the inventory of systems, who reviews the output, and the notices the European regulation asks for, which did not exist back then.